Digitala Vetenskapliga Arkivet

Change search
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf
Augmenting Software Bills of Materials with Software Vulnerability Description: A Preliminary Study on GitHub
Blekinge Institute of Technology, Faculty of Computing, Department of Software Engineering.ORCID iD: 0000-0002-0679-4361
University of Sannio, Italy.ORCID iD: 0000-0002-0340-9747
University of Salerno, Salerno, Italy.ORCID iD: 0000-0003-4880-3622
University of Salerno, Salerno, Italy.ORCID iD: 0000-0003-0024-7508
2025 (English)In: FSE Companion '25: Proceedings of the 33rd ACM International Conference on the Foundations of Software Engineering / [ed] Li, J, Association for Computing Machinery (ACM), 2025, p. 631-635Conference paper, Published paper (Refereed)
Abstract [en]

Software Bills of Material (SBOMs) are becoming a consolidated-and often enforced by governmental regulations-way to describe software composition. However, based on recent studies, SBOMs suffer from limited support for their consumption and lack information beyond simple dependencies, especially regarding software vulnerabilities. This paper reports the results of a preliminary study in which we augmented SBOMs of 40 open-source projects with information about Common Vulnerabilities and Exposures (CVE) exposed by project dependencies. Our augmented SBOMs have been evaluated by submitting pull requests and by asking project owners to answer a survey. Although, in most cases, augmented SBOMs were not directly accepted because owners required a continuous SBOM update, the received feedback shows the usefulness of the suggested SBOM augmentation.

Place, publisher, year, edition, pages
Association for Computing Machinery (ACM), 2025. p. 631-635
Keywords [en]
SBOM, Software repositories, VEX, Vulnerabilities management
National Category
Software Engineering
Identifiers
URN: urn:nbn:se:bth-28600DOI: 10.1145/3696630.3728513ISI: 001593214400070Scopus ID: 2-s2.0-105013970463ISBN: 9798400712760 (print)OAI: oai:DiVA.org:bth-28600DiVA, id: diva2:1995498
Conference
33rd ACM International Conference on the Foundations of Software Engineering, FSE Companion 2025, Trondheim, June 23-27, 2025
Part of project
SERT- Software Engineering ReThought, Knowledge FoundationSESAM – Secure Software Engineering Through Sensible AutoMation, Knowledge Foundation
Funder
Knowledge Foundation, 20230087Knowledge Foundation, 20180010Available from: 2025-09-05 Created: 2025-09-05 Last updated: 2025-12-15Bibliographically approved

Open Access in DiVA

fulltext(510 kB)29 downloads
File information
File name FULLTEXT01.pdfFile size 510 kBChecksum SHA-512
30be54297d810541cabc7fcbb50d436b547b671b19e9f7c33c8b3fe6c14e2bd052d9992c5a298c0e4dafac5e3287d26c77b6cce786c7b7d6d97a5e9d826daf60
Type fulltextMimetype application/pdf

Other links

Publisher's full textScopus

Search in DiVA

By author/editor
Fucci, DavideDi Penta, MassimilianoRomano, SimoneScanniello, Giuseppe
By organisation
Department of Software Engineering
Software Engineering

Search outside of DiVA

GoogleGoogle Scholar
Total: 29 downloads
The number of downloads is the sum of all downloads of full texts. It may include eg previous versions that are now no longer available

doi
isbn
urn-nbn

Altmetric score

doi
isbn
urn-nbn
Total: 972 hits
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf